First published: Wed Apr 11 2018(Updated: )
S12700 V200R005C00, V200R006C00, V200R006C01, V200R007C00, V200R007C01, V200R007C20, V200R008C00, V200R008C06, V200R009C00, V200R010C00, S7700 V200R001C00, V200R001C01, V200R002C00, V200R003C00, V200R005C00, V200R006C00, V200R006C01, V200R007C00, V200R007C01, V200R008C00, V200R008C06, V200R009C00, V200R010C00, S9700 V200R001C00, V200R001C01, V200R002C00, V200R003C00, V200R005C00, V200R006C00, V200R006C01, V200R007C00, V200R007C01, V200R008C00, V200R009C00, V200R010C00 have an improper authorization vulnerability on Huawei switch products. The system incorrectly performs an authorization check when a normal user attempts to access certain information which is supposed to be accessed only by authenticated user. Successful exploit could cause information disclosure.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei S12700 Firmware | =v200r005c00 | |
Huawei S12700 Firmware | =v200r006c00 | |
Huawei S12700 Firmware | =v200r006c01 | |
Huawei S12700 Firmware | =v200r007c00 | |
Huawei S12700 Firmware | =v200r007c01 | |
Huawei S12700 Firmware | =v200r007c20 | |
Huawei S12700 Firmware | =v200r008c00 | |
Huawei S12700 Firmware | =v200r008c06 | |
Huawei S12700 Firmware | =v200r009c00 | |
Huawei S12700 Firmware | =v200r010c00 | |
Huawei S12700 | ||
Huawei S7700 Firmware | =v200r001c00 | |
Huawei S7700 Firmware | =v200r001c01 | |
Huawei S7700 Firmware | =v200r002c00 | |
Huawei S7700 Firmware | =v200r003c00 | |
Huawei S7700 Firmware | =v200r005c00 | |
Huawei S7700 Firmware | =v200r006c00 | |
Huawei S7700 Firmware | =v200r006c01 | |
Huawei S7700 Firmware | =v200r007c00 | |
Huawei S7700 Firmware | =v200r007c01 | |
Huawei S7700 Firmware | =v200r008c00 | |
Huawei S7700 Firmware | =v200r008c06 | |
Huawei S7700 Firmware | =v200r009c00 | |
Huawei S7700 Firmware | =v200r010c00 | |
Huawei S7700 | ||
Huawei S9700 Firmware | =v200r001c00 | |
Huawei S9700 Firmware | =v200r001c01 | |
Huawei S9700 Firmware | =v200r002c00 | |
Huawei S9700 Firmware | =v200r003c00 | |
Huawei S9700 Firmware | =v200r005c00 | |
Huawei S9700 Firmware | =v200r006c00 | |
Huawei S9700 Firmware | =v200r006c01 | |
Huawei S9700 Firmware | =v200r007c00 | |
Huawei S9700 Firmware | =v200r007c01 | |
Huawei S9700 Firmware | =v200r008c00 | |
Huawei S9700 Firmware | =v200r009c00 | |
Huawei S9700 Firmware | =v200r010c00 | |
Huawei S9700 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-15327 is medium (4.3).
Huawei S12700 Firmware versions V200R005C00 to V200R010C00 and Huawei S7700 Firmware versions V200R001C00 to V200R010C00 are affected by CVE-2017-15327.
The Common Weakness Enumeration (CWE) ID for CVE-2017-15327 is CWE-200.
CVE-2017-15327 has a severity value of 4.3, which is medium.
To fix CVE-2017-15327, update your Huawei S12700 Firmware to versions V200R011C00 or later, and update your Huawei S7700 Firmware to versions V200R011C00 or later.